Jira 项目向无权查看的用户显示

发布于 2024-12-27 13:49:22 字数 712 浏览 2 评论 0原文

在 Jira (4.0) 中,在全局权限下,我有 Jira Users 组,其中包含两个组:jira-users 和 jira-login。当我开始在这家公司工作时,只有 jira-users 组,但我添加了 jira-login,以便我可以从 jira-users 中删除用户,但仍然让他们能够登录。拥有 jira-users 权限的每个人都对 Jira 中的每个项目都拥有特定的权限,我不想更改该组对每个受影响的项目/权限方案的访问权限。

最终,我想做的是让一个新的群体——供应商——对我们的项目拥有有限的访问权限。因此,供应商只是 jira-login 的成员,并且仅限于供应商。普通用户是 jira-login 和 jira-user 的成员,但由于他们是 jira-users 的一部分,因此他们仍然可以在不属于 jira-login 组的情况下登录。

我遇到的问题是供应商可以看到我希望他们看到的项目,但也可以看到一些我没有授予他们查看权限的项目。我想消除供应商对这些不需要的项目的可见性。注意:为了让供应商看到选定的项目,我在我希望他们看到的每个项目上添加了供应商组和用户项目角色。

在每个不需要的可见项目的项目角色下,唯一有权访问用户(或除 admin 之外的任何其他项目角色)的组是 jira-users。我不知道 jira-users 组之外的人如何看到这些项目。

我似乎找不到这些供应商的共同点方案/设置。当然,新创建的 jira-login 组没有任何我未手动输入的访问权限。正确的?

有什么建议吗?谢谢。

In Jira (4.0), under Global Permissions, I have the Jira Users group containing two groups, jira-users and jira-login. When I started at this company, there was only the jira-users group, but I added jira-login so that I could remove users from jira-users and still have them be able to login. Everyone with jira-users permissions has specific permissions across every project in Jira and I didn't want to have to change that group's access on every project/permissions scheme affected.

Ultimately, what I'm trying to do is have a new group, Suppliers, have limited access to our projects. So a supplier is a member of jira-login and Suppliers only. Regular users are members of both jira-login and jira-users, although since they are a part of jira-users, they can still login without being part of the jira-login group.

The problem I'm having is that suppliers can see the projects that I want them to, but also a few projects that I didn't give them permissions to see. I want to remove the visibility of these unwanted projects for suppliers. NOTE: to let the suppliers see the select projects, I added the Suppliers group the the Users project role on each project that I want them to see.

Under project roles for each of this unwantedly visible projects, the only groups that have access to the Users (or any other project role besides admin) is jira-users. I have no idea how people outside of the jira-users group can see these projects.

I cannot seem to find the common denominator scheme/setting that these suppliers have. Certainly the newly created jira-login group doesn't have any sort of access that I didn't enter in manually. Right?

Any suggestions? Thanks.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

没有伤那来痛 2025-01-03 13:49:22

与其拥有 jira-login 和 jira 用户组,不如创建不涉及 jura-user 组的新组(这可能会导致奇怪的行为)。根据我的阅读,似乎所有用户都需要成为 Jira-users 组的一部分才能登录。

然后,拥有仅包含您想要的组的权限方案应该能够锁定未经授权的组。

Instead of having a jira-login and jira user group it might be better to create new groups that don't involve the jura-user group(this might cause odd behavior). From what I have read it seems that all users need to be a part of the Jira-users group to even log in.

Then having permission schemes that only include the groups that you want should be able to lock out unauthorized groups.

佞臣 2025-01-03 13:49:22

查看问题的能力由浏览项目权限控制。检查供应商可以意外查看的组的权限方案,并查看谁拥有该权限。它可以是一个群体,也可以是一个角色。从其中删除供应商,他们将无法查看该项目的问题。

更多信息请访问 http://confluence.atlassian.com/display/JIRA/Managing+项目+权限

The ability to view issues is controlled by the Browse Projects permission. Check the permission scheme for a group that Suppliers can unexpectedly view and see who has that permission. It may be a group or a role. Remove the Suppliers from that and they won't be able to view that project's issues.

More info at http://confluence.atlassian.com/display/JIRA/Managing+Project+Permissions

夜光 2025-01-03 13:49:22

该问题是由“浏览项目”权限中的“当前受让人”或“报告者”引起的。奇怪的行为。留意这个。

The issue was caused by having either "Current Assignee" or "Reporter" in the "Browse Project" permission. Strange behavior. Watch out for this one.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文